Cybersecurity

Cybersecurity
Former US Soldier Gets 70 Months for Hacking AT&T and Verizon
Cameron John Wagenius sentenced to 70 months in prison for hacking 10 U.S. technology and telecommunications companies while on active duty.
Application Security
Carbonato Botnet Hijacks Docker Hosts to Deploy Telegram-Controlled AI
Carbonato malware installs Hermes Agent AI framework on exposed Docker daemons, then controls the agent via Telegram with a modified 39-line prompt.
DC Health Agency Exposes 400,000 Medicaid Beneficiary Records Online
Application Security
DC Health Agency Exposes 400,000 Medicaid Beneficiary Records Online
Washington D.C. Department of Health Care Finance exposed approximately 400,000 Medicaid beneficiary records through a misconfigured web portal accessible without authentication.
Cybersecurity
Suspected North Korean Hackers Steal $351.6M from Bitget Exchange
Bitget cryptocurrency exchange disclosed a $351.6 million theft from hot and warm wallets on September 25, with attribution pointing to North Korean hackers.
Application Security
Roundcube Webmail SQL Injection Flaw Exploited Four Months After Patch
Canadian Centre for Cyber Security confirmed active exploitation of CVE-2026-48842, an unauthenticated SQL injection flaw in Roundcube Webmail patched in May.
Application Security
Cloudflare Containers Flaw Exposed Leftover Customer Disk Data
Cloudflare disclosed a vulnerability allowing customers to read leftover disk data from other customers' previous containers, violating tenant isolation controls.
Application Security
CISA Adds WSO2 and Adobe Commerce Flaws to KEV Catalog
CISA added CVE-2026-5430 in WSO2 API Control Plane and an Adobe Commerce flaw to its Known Exploited Vulnerabilities catalog following active exploitation.
Application Security
AI Agents Power Mass Attack Stealing 600K Credit Cards from Retailers
Threat actors used three open-source AI agent frameworks to compromise over 100 online retailers and steal more than 600,000 credit card records automatically.
Application Security
MacSync Malware Variant Uses iCloud Calendars for Command and Control
Security researchers disclosed a MacSync malware variant that abuses public iCloud calendar events as a command-and-control channel to deliver payloads to macOS.
Cybersecurity
SalesBleed Flaws Enable Zero-Click CRM Data Theft from Salesforce
Security researchers disclosed SalesBleed vulnerabilities in Salesforce Agentforce allowing zero-click CRM data theft and anonymous phishing attacks.